Назад
Company hidden
3 часа назад

Application Security Engineer (Cybersecurity)

180 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Cybersecurity): Strengthening application security for open-source data protection applications and the Trusted Data Format platform with an accent on secure development, vulnerability management, and security tooling. Focus on threat modeling, code audits, automated threat hunting, and integrating SAST, DAST, IAST, and SCA tools into development pipelines.

Location: Washington, DC - Remote

Salary: $180,000–$200,000/year

Company

hirify.global develops data protection applications and the open Trusted Data Format platform, enabling secure data sharing, privacy, and control for enterprises and government agencies.

What you will do

  • Collaborate with engineering, Site Reliability Engineering, and other stakeholders to strengthen security practices throughout the software development lifecycle.
  • Identify and implement application security improvements independently.
  • Build, manage, and automate vulnerability management processes, prioritizing and remediating findings from scans, penetration tests, and bug bounties.
  • Conduct threat modeling, code audits, and secure design reviews, providing actionable recommendations.
  • Establish threat hunting capabilities and enhance security-event logging.
  • Integrate and manage dynamic and static code analysis tools within development pipelines.

Requirements

  • 4+ years of experience in secure development or application security.
  • Deep knowledge of authentication, web architecture, cryptography, and application security concepts.
  • Experience with Node.js and Go.
  • Experience running bug bounty, penetration testing, and vulnerability scanning programs.
  • Experience setting up and maintaining SAST, DAST, IAST, and SCA tooling.
  • Experience with security assessment tools such as Burp, ZAP, Qualys, or Nessus, and with building and maintaining WAF solutions.

Nice to have

  • Familiarity with FedRAMP, SOC 2, HIPAA, and related security standards and regulations.
  • Familiarity with GCP, AWS, and Kubernetes infrastructure security.

Culture & Benefits

  • Flexible PTO policy and 14 company holidays.
  • $1,500 annual learning and development stipend.
  • Flexible working environment with support for personal appointments and emergencies.
  • Medical, dental, vision, parental, bereavement, and employee assistance benefits.
  • 401(k) contribution, stock options, and a flat 3% retirement-account contribution.
  • Inclusive workplace with emphasis on diversity, belonging, and psychological safety.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →